SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Google Issues Emergency Fix for Actively Exploited Chrome Zero-Day – CVE-2025-6554

Google Issues Emergency Fix for Actively Exploited Chrome Zero-Day – CVE-2025-6554

Jul 1, 2025By Moulik Arora3 min read

Google has released another emergency security update for its Chrome browser, addressing a high-severity zero-day vulnerability actively exploited in the wild. This vulnerability, CVE-2025-6554, marks the fourth Chrome zero-day fixed in 2025. It involves a type confusion flaw in Chrome’s V8 JavaScript and WebAssembly engine, which attackers exploit to compromise systems.

Vulnerability Details

The issue stems from a type confusion vulnerability in the V8 JavaScript and WebAssembly engine, which causes the program to misinterpret object types during execution. If successfully exploited, this flaw can result in arbitrary memory access, reading from and writing to memory outside the allocated buffer.

Attackers can exploit this flaw to trigger memory corruption by luring victims to maliciously crafted websites, which can potentially lead to arbitrary code execution.

This vulnerability affects Chrome across Windows, macOS, and Linux platforms and has been assigned a high severity rating by the NVD.

Impact & Exploit Potential

The consequences of this vulnerability are critical, especially since it is actively being exploited:

    • Arbitrary Code Execution: Allows attackers to run unauthorized code on the victim’s device.
    • Data Theft: Exploitation could expose sensitive data stored in memory.
    • System Compromise: May result in complete control over the affected system.

Google has confirmed the active exploitation of CVE-2025-6554, emphasizing the urgency of applying the patch.

Tactics, Techniques, and Procedures (TTPs)

This attack aligns with tactics from the MITRE ATT&CK framework:

    • TA0002 – Execution: Exploiting vulnerabilities to execute malicious code.
    • T1203 – Exploitation for Client Execution: Victims are tricked into visiting malicious web pages crafted to trigger the flaw.

State-sponsored actors and cybercriminal groups for espionage, spyware deployment, or surveillance campaigns often leverage such zero-days.

Affected Products

The vulnerability impacts the following versions of Google Chrome:

    • Windows: Versions before 138.0.7204.96/.97
    • macOS: Versions before 138.0.7204.92/.93
    • Linux: Versions before 138.0.7204.96

Other Chromium-based browsers, such as Microsoft EdgeBraveOpera, and Vivaldi, may also be affected and should be updated as soon as patches are released by their respective vendors.

Discovery and Mitigation

CVE-2025-6554 was discovered by Clément Lecigne of Google’s Threat Analysis Group (TAG) on June 25, 2025. Google responded promptly by rolling out a configuration change to the Stable channel the following day. However, a complete fix requires users to update Chrome to the latest version manually.

To apply the update:

Navigate to Settings > Help > About Google Chrome — the browser will automatically check for and install the latest version.

Real-World Observations

This is the fourth Chrome zero-day actively exploited in 2025, following vulnerabilities like CVE-2025-2783 and CVE-2025-4664, which were used in targeted espionage campaigns.

Google TAG continues to monitor exploitation by nation-state actors targeting high-risk individuals such as journalists, political dissidents, and activists.

To limit further exploitation, Google withheld technical details until most users updated their browsers.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated solution that instantly remediates vulnerabilities being exploited in the wild. It supports all major platforms, including Windows, Linux, macOS, and over 550+ third-party applications.

    • Enables safe patch testing before deployment
    • Supports rollback in case of patch failure or instability
    • Ensures the fastest and most accurate vulnerability remediation

Experience the fastest and most accurate patching software here

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026